CVE-2022-22318: Critical severity ibm curam social program management vulnerability
Published Jun 20, 2022
·Updated
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Software
8 affected components
IBM Curam Social Program Management=8.0.0
IBM Curam Social Program Management=8.0.1
HP HP-UX
IBM AIX
IBM Z\/os
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jun 20, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22318?
CVE-2022-22318 is considered to have a medium severity due to the potential for user impersonation.
2
How do I fix CVE-2022-22318?
To fix CVE-2022-22318, ensure your application invalidates the session after logout.
3
What software versions are affected by CVE-2022-22318?
CVE-2022-22318 affects IBM Curam Social Program Management versions 8.0.0 and 8.0.1.
4
Can CVE-2022-22318 lead to unauthorized access?
Yes, CVE-2022-22318 could allow an authenticated user to impersonate another user, leading to unauthorized access.
5
Is there a workaround for CVE-2022-22318?
There is no official workaround for CVE-2022-22318; the recommended action is to apply the fix as soon as possible.